Compliance Node Overview
MITRE ATT&CK T1110.002 (Password Cracking) is an Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained. OS Credential Dumping can be used to obtain password hashes, this may only get an adversary so far when Pass the Hash is not an option. Further, adversaries may leverage Data from Configuration Repository in order to obtain hashed credentials for network devices. Affected platforms: Linux, macOS, Windows, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1027 Password Policies, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-20, CA-07, CM-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1110/002/
SHA-256 integrity: 4d8436e03d17cd863ca15cd29da4fb36cda8ea01224acffd938a58f0db69a0ff
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1110.002: Password Cracking (https://attack.mitre.org/techniques/T1110/002/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access